Privacy policy
What PokéTrack does with your data
Last updated: August 10, 2026
1. Data controller
The data controller is Arnaud de Cuniac, a natural person, publisher of the PokéTrack service in a personal, non-professional capacity.
Contact: a.decuniac@gmail.com
Given the nature and volume of the processing involved, no data protection officer has been appointed.
2. Guiding principle
PokéTrack is a personal project. Only the data required to operate it is collected.
The Service carries no audience measurement, no advertising tracker and no behavioral analytics. Your data is never sold, rented or passed to third parties for commercial purposes, and is subject to no profiling and no automated decision-making.
3. Data collected
a. Account
Your name, your email address, whether that address has been verified, and the dates the account was created and last modified. If you sign in with a Google account, that account’s identifier and, where applicable, the profile picture address provided by Google.
b. Authentication material
The fingerprint of your password, stored hashed and never in clear text. The tokens issued by Google if you use that sign-in method, which may contain the email address of that Google account, along with the permissions granted to the Service. The one-time codes sent by email, stored hashed, along with address verification and password reset tokens.
During a Google sign-in or account link, a temporary technical state is also recorded: it holds the return address to the Service, a single-use security key and, in the case of a link, the email address and identifier of the account concerned.
c. Sessions
A session token and its expiry date, together with the IP address and browser identifier (user-agent) recorded when the session was opened.
d. Collection
The identifiers of the cards you declare you own, along with the date they were added. No data is retrieved from the game: this list comes solely from what you enter.
e. Preferences
Whether secret cards should be counted towards your progress.
f. Security
Request rate-limiting counters, stored under a key that pairs your IP address with the route called. An IPv4 address is kept whole; an IPv6 address is truncated to its first 64 bits, both here and for sessions.
No sensitive data within the meaning of Article 9 of the GDPR is collected. The Service processes no payment data, since it involves no payments.
4. Purposes and legal bases
| Purpose | Data involved | Legal basis |
|---|---|---|
| Creating and managing your account | a, b | Performance of the contract formed by the terms of use |
| Authenticating you and keeping your session open | b, c | Performance of the contract |
| Sending verification and password reset emails | a | Performance of the contract |
| Recording your collection and computing your progress | d, e | Performance of the contract |
| Protecting the Service against abuse and intrusion attempts | c, f | Legitimate interest in the security of the Service |
| Answering your requests | a and the content of your message | Legitimate interest in handling incoming inquiries |
5. Emails sent
The only emails sent are transactional: address verification, password reset, and a notice when someone attempts to sign up with an address already tied to an account.
No newsletter and no promotional email is ever sent.
6. Cookies and local storage
The Service sets four cookies, all strictly necessary for it to work. As such they are exempt from prior consent, and no cookie banner is displayed.
| Cookie | Role | Lifetime |
|---|---|---|
__Secure-better-auth.session_token | Keeps your session open. Signed cookie, not readable by page JavaScript | 30 days |
__Secure-better-auth.session_data | Caches the session to avoid a database read on every page | 5 minutes |
__Secure-better-auth.state | Protects a Google sign-in or account link against request forgery | 5 minutes |
i18n_redirected | Remembers the language you chose | 1 year |
The __Secure- prefix is added by the authentication layer when the Service is served over HTTPS, which is the case in production. Outside HTTPS the first three cookies carry the same names without that prefix.
The Service also stores two pieces of information in your browser’s local storage: the cards most recently searched in the booster tool, under a key prefixed poketrack.recent-target-cards, and your theme preference (light, dark or system). This information is never sent to the server and disappears if you clear the site data.
7. Recipients and processors
Your data is only accessible to the publisher and to the following technical providers, acting on the publisher’s instructions:
| Provider | Role | Data involved | Location |
|---|---|---|---|
| Vercel Inc. | Site hosting and image delivery | Data passing through the Service, technical logs | United States, delivered through a global network |
| Neon | Database | Account, authentication, sessions, collection, preferences | European Union |
| Resend | Sending transactional emails | Name, email address, email content | United States |
| Google account sign-in, only if you choose that method | Authentication material | United States |
Your data may also be disclosed to an administrative or judicial authority where the law requires it.
8. Transfers outside the European Union
The database, which holds the bulk of your data, is hosted within the European Union.
The hosting, email and authentication providers are established in the United States. Transfers to those providers are governed by the standard contractual clauses adopted by the European Commission and, where applicable, by their adherence to the EU / US data protection framework.
9. Retention periods
| Data | Period |
|---|---|
| Account, collection and preferences | For as long as the account exists. No automatic deletion is applied for inactivity |
| Sessions | Valid for 30 days, or until you sign out |
| One-time codes and reset tokens | Valid for 1 hour |
| Google sign-in and link states | Valid for 10 minutes |
| Rate-limiting counters | A few minutes |
| Emails you send to the publisher | As long as needed to handle your request |
Once the stated period has passed, a session, a one-time code, a reset token or a sign-in state stops being valid and can no longer be used. The matching row is not erased automatically, however: it stays in the database until a cleanup is carried out.
Deleting your account, requested as described in section 10, erases the account itself, your sign-in credentials, your sessions, your collection and your preferences. Three technical sets are not tied to the account and therefore do not disappear with it: verification and reset codes, which hold the email address they were sent to; Google sign-in and link states, which hold the return address and, for a link, the email address and identifier of the account; and rate-limiting counters, which hold an IP address. You may ask for those to be erased in the same request. Residual copies may also remain for a few days in the host’s backups, before being overwritten in turn.
10. Your rights
Under the GDPR, you have the right to access, rectify, erase, restrict and object to the processing of your data, as well as the right to data portability and the right to set instructions on what becomes of your data after your death.
These rights are exercised by email to a.decuniac@gmail.com. You will receive a reply within a maximum of 30 days. A verification element may be requested if there is serious doubt about your identity.
If you believe your rights are not being respected, you may lodge a complaint with the French data protection authority, Commission nationale de l’informatique et des libertés, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or at www.cnil.fr.
11. Security
Exchanges with the Service are encrypted over HTTPS. Passwords and one-time codes are stored hashed. Session cookies are signed and not readable by page JavaScript. Every authentication route is rate limited, with tighter thresholds on sign-in, sign-up and password reset. Database access is restricted.
Since no system is infallible, and the Service is a personal project, no guarantee of absolute security can be given. If you discover a vulnerability, please write to the contact address rather than disclosing it publicly.
12. Minors
The Service is reserved for people aged 15 or over, in accordance with Article 5 of the terms of use. No data is knowingly collected from anyone younger. If such an account is reported, it is deleted and its data erased.
13. Changes
This policy may change, in particular if the way the Service works or the providers it relies on change. The date it was last updated appears at the top of the document.
In the event of a substantial change, users holding an account are informed by email or through a visible notice on the Service.
14. Language
This policy is written in French. The English translation is provided for information only: in the event of any discrepancy, the French version prevails.